Beware of new-look phishing attacks

Jun 25, 2013

The number of Internet users who faced phishing attacks over the last 12 months has grown from 19,9-million to 37,3-million – an increase of 87%. Facebook, Yahoo, Google and Amazon are among main targets of cybercriminals.

This is according to “The evolution of phishing attacks 2011-2013” survey carried out by Kaspersky Lab, based on data from the Kapersky Security Network cloud service, which shows that what was once a subset of spam has evolved into a rapidly growing cyber-threat in its own right.

Phishing is a form of Internet fraud in which criminals create a fake copy of a popular site (an e-mail service, an Internet banking Web site or a social networking site) and try to lure the users to these rogue Web pages. The unsuspecting user enters their login information and passwords into these carefully forged Websites as they normally would, but these access credentials are instead sent to the cybercriminals.

The scammers can then use this stolen personal information, bank credentials, or passwords to steal the users’ money, to distribute spam and malware via the compromised e-mail or social networking accounts, or they can simply sell their databases of stolen passwords to other criminals.

For a long time, phishing was regarded as a variation of typical spam e-mails. However, the data from this survey confirms that the scale of phishing attacks has reached such a significant level that they should be regarded as a dangerous threat category of their own, not merely an off-shoot of general spam.

In fact, e-mail is no longer the most common delivery mechanism for phishing e-mails. For example, only 12% of all registered phishing attacks were launched via spam mailings. The other 88% of cases came from links to phishing pages which people followed while using a Web browser, a messaging system (such as Skype) or otherwise interacting with the computer.

During the survey, Kaspersky Lab specialists compared data on phishing attacks from over 50-million Kaspersky Security Network users between 1 May 2012 and 30 April 2013 with figures for the equivalent period of 2011-2012.

In 2012-2013, phishers launched attacks affecting an average of 102 100 people worldwide each day – twice as many as in 2011-2012.

Phishing attacks most often target users in Russia, the US, India, Vietnam and the UK. Vietnam, the US, India and Germany have the greatest number of attacked users – the total number of attacks in these regions has doubled since last year.
The majority of the servers hosting phishing pages were registered in the US, the UK, Germany, Russia and India.

The number of unique attack sources – such as fraudulent Web sites and servers – has more than tripled from 2012-2013. More than half (56%) of all identified unique attack sources were found in just 10 countries, which means the attackers have a small set of preferred “home bases” to launch their attacks.

The services of Yahoo!, Google, Facebook and Amazon were most often attacked by phishers – 30% of all registered incidents involved fake versions of their sites.
More than 20% of all phishing attacks mimicked banks and other financial organisations, with American Express, PayPal, Xbox live and Twitter all in the top 30 most targeted sites.

“The volume and variety of phishing attacks detected during the survey indicates that phishing is not merely one tool among many for the illegal enrichment of fraudsters, but represents a significant and visible threat. These attacks are relatively simple to organise and are demonstrably effective, attracting an increasing number of cybercriminals to this type of illegal activity.